← Back to Insights
Executive Summary

The PRA's Supervisory Statement SS1/23 — the most significant model risk management framework issued by a UK regulator since the financial crisis — came into legal force on 17 May 2024. Its five principles apply to all material models used by regulated UK banks, building societies, and PRA-designated investment firms. They explicitly include End User Computing tools: spreadsheets, SAS programmes, and offline calculations that sit outside formal model inventory systems.

Most compliance programmes focused on the visible model estate — the IFRS 9 models, the IRB capital models, the stress testing frameworks. These were already inventoried, already partially governed. The EUC estate beneath them was a different matter: largely undocumented, informally maintained, and absent from most model risk governance frameworks entirely.

More than a year after the legal deadline, that gap remains the most common SS1/23 compliance deficiency identified in supervisory engagement. It is also the most addressable — if the organisation knows where to start.

What SS1/23 actually requires

SS1/23 sets out five principles for model risk management. They are overarching in scope — the PRA was deliberate about this. The statement applies to all types of models used to inform business decisions, whether developed in-house or externally, regardless of technology, and including models used for financial reporting purposes.

The explicit inclusion of EUC tools was not accidental. The PRA observed, during its supervisory work in the years preceding SS1/23, that some of the most material model risk in regulated firms was sitting in assets that had never been formally identified as models at all — spreadsheets built by business analysts, SAS programmes maintained by a single person, Access databases feeding regulatory returns with no documentation and no governance trail.

Principle 1
Model Identification & Classification

Firms must identify all models in use — including EUC tools — and classify them by materiality and risk. Most EUC assets have never been inventoried at all.

⚠ Common EUC gap: absent from model inventory

Principle 2
Governance & Policies

Clear ownership, documented methodology, and Board-level oversight of model risk. EUC assets typically have informal ownership at best — often reverting to whoever maintains the file.

⚠ Common EUC gap: no formal owner, no documented methodology

Principle 3
Model Development & Implementation

Models must be developed with documented rationale, tested, and formally approved before use. Most EUC tools were built to solve an immediate problem — documentation came later, if at all.

⚠ Common EUC gap: no development documentation or approval record

Principle 4
Model Validation

Independent validation of model methodology, assumptions, and outputs. The PRA expects this to be performed by a function independent of model development. For EUC tools, independent validation has almost never been performed.

⚠ Common EUC gap: never independently validated

Principle 5
Model Risk Mitigants

Where a model is known to underperform or carries identified deficiencies, firms must have clear policies for restricting its use, applying post-model adjustments, and escalating concerns to the appropriate people. For most EUCs, no such process exists — known issues get quietly worked around rather than formally flagged, restricted, or escalated.

⚠ Common EUC gap: no formal process for restricting, adjusting, or escalating known issues

"The PRA did not write EUC tools into SS1/23 as an afterthought. It wrote them in because supervisory experience showed they were where the real risk was hiding."

The compliance programme that stopped too soon

When SS1/23 was published in May 2023 and firms had twelve months to prepare, most compliance programmes followed a logical prioritisation: address the formal model inventory first, then work outward. The IRB capital models, the IFRS 9 impairment models, the stress testing frameworks — these were the assets already known, already partially governed, and carrying the highest regulatory visibility.

The EUC estate was different. It was not on the model inventory because it had never been inventoried. It was not in the governance framework because nobody had formally decided it needed to be. And by the time the May 2024 deadline arrived, many firms had completed their visible compliance programme while the EUC layer beneath it remained untouched.

5
SS1/23 principles — all five explicitly apply to EUC tools and offline spreadsheet calculations
Source: PRA SS1/23, Bank of England
May 2024
Legal deadline passed — PRA supervisory engagement with first cohort of firms already underway
Source: PRA
s.166
Skilled person review — the PRA's enforcement mechanism for firms falling short of SS1/23 expectations
Source: Deloitte / PRA
Supervisory Risk — Section 166 Review

Deloitte's pre-implementation analysis noted that the PRA will expect firms within scope to demonstrate a high level of compliance from day one — and that the probability of the PRA commissioning a skilled person report (s.166 review) for banks falling short of SS1/23 expectations is high.

A s.166 review is not a voluntary exercise. It is conducted by an external reviewer appointed by and reporting to the PRA, at the firm's expense. The findings go directly to the regulator. For firms with material EUC assets feeding regulatory outputs that have never been through a governance framework, this is a live and foreseeable risk — not a theoretical one.

What closing the gap requires

Closing the SS1/23 EUC gap is not a single action. It is a structured programme of work that begins with knowing what you have and ends with being able to demonstrate, to a regulator, that every material EUC asset has been identified, documented, owned, and assessed.

The starting point is always the same: a systematic inventory and deconstruction of the EUC estate. Not a spreadsheet list of file names — a documented understanding of what each asset does, what data it uses, what logic it applies, what outputs it produces, and what governance it currently has or lacks.

What "Documented" Means to the PRA

SS1/23 Principle 2 requires that model methodology is documented to a standard that enables an independent reviewer to understand and reproduce the model without requiring assistance from the model developer. For most EUC assets, this standard has never been met — the documentation, where it exists at all, is limited to cell comments and an incomplete change log.

Principle 4 requires that validation is performed by a function independent of model development. For EUC tools built and maintained by business teams, this means the validation cannot be performed by the same team — or even the same business unit. External review by a specialist with model risk governance experience is what the PRA expects.

How Greywood Analytics Helps

Structured deconstruction that closes the SS1/23 EUC gap.

A Greywood Analytics engagement is specifically designed to produce the documentation that SS1/23 requires — and to position each asset for the governance steps that follow. For every EUC asset in scope, we deliver:

Our deconstruction constitutes the independent review that SS1/23 Principle 4 requires — conducted by a specialist with Financial Services model risk experience, outside the business unit, with full documented evidence of findings.

First deliverable pack typically received within 2–3 working days of engagement start.

The gap is still closeable

The May 2024 deadline has passed. But SS1/23 compliance is not a binary state — it is an ongoing supervisory expectation. Firms that can demonstrate a credible, evidence-based programme of EUC governance remediation are in a materially better position than firms that cannot, regardless of where that programme started.

The PRA's supervisory engagement is ongoing. The s.166 risk is real. And the EUC assets that have never been through a governance framework — the ones built by analysts who have since left, running on scheduled jobs nobody fully understands, feeding outputs that go to the Board and the regulator — are still there.

The gap is still closeable. The question is whether your organisation closes it proactively, or waits for a supervisory conversation that forces the issue on someone else's timeline.

"SS1/23 did not create the EUC risk. It created the obligation to address it — and a deadline that has already passed."
Greywood Analytics

If your organisation has material EUC assets that have not yet been assessed against SS1/23, we can help you understand the gap and close it — starting with a no-commitment scoping conversation.

Start a Conversation